DevSecOps Security Architect
hace 9 días
Madrid
About the Company: NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. About the Role: We are looking for a talented and proactive DevSecOps specialist. Main responsibility will be to embed security into the software development lifecycle, automate controls, and ensure applications, pipelines and platforms remain secure and compliant with best practices and regulatory standards. Key Responsibilities: • Define and implement Secure SDLC (sSDLC) and DevSecOps models., • Establish security policies and controls at each phase of the SDLC (requirements, design, implementation, verification, deployment, and maintenance)., • Align processes with industry standards such as OWASP, NIST SSDF, or Microsoft SDL., • Identify security requirements for applications., • Review and update threat models and risk assessments., • Perform both manual and automated code reviews (SAST, DAST, IAST, SCA) and implement automated scans in CI/CD pipelines (e.g., Jenkins, GitHub Actions)., • Integrate security tools (Fortify, Veracode, SonarQube, OWASP ZAP) within DevSecOps environments, ensuring early detection and remediation., • Support technical audits, vulnerability assessments, and remediation plans., • Design and deliver security awareness and training plans for developers, based on OWASP ASVS or Microsoft SDL guidelines., • Act as a liaison between technical teams, security teams, and management, effectively communicating risks and results to both technical and executive stakeholders., • Monitor KPIs (e.g., vulnerabilities detected, remediation time, testing coverage) and drive continuous improvement initiatives across the process., • Provide support during application security incidents and collaborate with incident response teams when critical vulnerabilities are identified in production. What will make you successful in this role? • Fluency in English (at least B2+ or C1) and EU nationality., • Bachelor’s or Master’s degree in Computer Science, Telecommunications, or a related field, with cybersecurity specialization., • At least 3 years of experience in Application Security (AppSec), Secure SDLC, or secure development., • Strong knowledge of OWASP ASVS, OWASP SAMM, threat modeling, and security frameworks., • Experience in code review (manual and automated), vulnerability scanning, and leadership in CI/CD pipelines., • Proficiency with SAST, DAST, and IAST tools, as well as DevOps technologies., • Valuable certifications: CISSP, CSSLP, CEH, OSCP, CISM., • Excellent communication skills and ability to work with multidisciplinary teams, including delivering effective internal training., • Strong analytical mindset and detail-oriented approach., • Proactive and self-driven in critical environments., • Strategic vision with strong cross-functional collaboration skills. We Offer: • Opportunities for professional development and continuous training., • An inclusive and multicultural work environment., • Participation in innovative and challenging projects at an international level., • Competitive benefits package. If you are passionate about cybersecurity and ready to start your career in an international environment, we invite you to apply and join our team!